A domain can have SPF, DKIM, and DMARC records published and still be freely spoofable, because DMARC has a monitoring mode that reports on failures without blocking a single message. Enforcement mode is the setting that turns those records from a reporting mechanism into an actual block, and it is the step a large share of domains never take.
01
What each record actually does
SPF (Sender Policy Framework) lists which mail servers are authorised to send on behalf of a domain. A receiving server checks the sending server's IP against this list.
DKIM (DomainKeys Identified Mail) attaches a cryptographic signature to outgoing mail, letting a receiving server verify the message wasn't altered in transit and genuinely came from a server holding the domain's private key.
DMARC (Domain-based Message Authentication, Reporting and Conformance) tells receiving servers what to do when a message fails both SPF and DKIM alignment, and it has three possible policies: "none" (report only, deliver anyway), "quarantine" (deliver to spam), and "reject" (block delivery entirely).
02
Why "none" is the default almost everyone starts with, and stays on
Moving straight to "reject" risks blocking legitimate mail from a service nobody remembered configures as a sender on the domain, a marketing platform, a support ticketing tool, an internal application that sends notification email. The safe rollout path is genuinely staged: publish DMARC in "none" mode first, review the aggregate reports it generates to find every legitimate sender, fix any that fail authentication, and only then move to "quarantine" and eventually "reject".
The problem is that the staged rollout is exactly the part that gets abandoned. A domain lands on "none", the immediate compliance box is checked, and the move to enforcement, the step that requires reading reports and iterating, never happens. A DMARC record sitting in "none" mode indefinitely provides visibility into spoofing attempts and stops none of them.
03
Why this matters more than anti-malware filtering alone
Business email compromise, an attacker impersonating an executive or a supplier to request a wire transfer or a change of banking details, typically contains no malicious attachment and no malicious link. It is a well-written email from a spoofed or lookalike domain. Anti-malware filtering has nothing to detect in a message like that. Authentication enforcement and impersonation detection, catching the spoofed domain or the display-name mismatch, are the controls that actually address this attack pattern, and they are frequently the ones organisations skip in favour of filtering that catches a different threat entirely.
04
The control NCA ECC names explicitly
NCA ECC-2:2024's Cybersecurity Defence domain names email protection as a control requiring deployment and central management, not a mail platform's out-of-the-box spam filter left on default. A DMARC record stuck in monitoring mode, with no one reviewing the reports it generates, does not meet that bar even though the record technically exists.
A free cybersecurity maturity assessment scores email, endpoint, and identity controls against the NIST Cybersecurity Framework in about 15 minutes, and will flag whether email authentication is one of the gaps worth closing first.
Need Expert Guidance?
Our team of specialists can help you navigate these challenges and build a tailored strategy for your organization.
Schedule a ConsultationAllo Technologies provides advisory and managed services across cybersecurity, cloud, and AI.
Frequently asked questions
Find answers to common questions about our services
Share this article
Related Reading
More insights from the Allo Technologies practice
Managed Security Pricing: MDR, SOC, and MSSP Models
What managed security really costs in the Kingdom: broken down by model, scope, and SLA so you can budget without surprises.
Read moreAI Governance ROI: Business Case for Executives
AI governance investments yield measurable returns through risk reduction, market access, and competitive advantage. Build your business case here.
Read moreNIST CSF 2.0 Mapped to NCA Requirements
Most of a NIST CSF 2.0 programme counts towards NCA compliance. A short, specific list does not, and that is where organisations fail reviews.
Read moreTalk to an Expert
Get personalized guidance from our senior security and compliance practitioners